Google just fixed 107 security flaws in Android — including two that hackers already used in real attacks.
The exploited bugs (CVE-2025-48633 & CVE-2025-48572) affect the Android Framework and could expose data or give attackers higher access.
The exploited bugs (CVE-2025-48633 & CVE-2025-48572) affect the Android Framework and could expose data or give attackers higher access.
ShadyPanda quietly turned trusted Chrome and Edge extensions into spyware.
Over 4.3 million installs in 7 years — some were even once verified by Google.
After silent updates in mid-2024, they began sending users’ browsing data and cookies to remote servers.
Over 4.3 million installs in 7 years — some were even once verified by Google.
After silent updates in mid-2024, they began sending users’ browsing data and cookies to remote servers.
Tomiris is back — and harder to spot.
Kaspersky reports the group is using Telegram & Discord as C2 servers to hide attacks on government networks in Russia & Central Asia.
Its new malware — written in Python, Rust, Go, PowerShell & C#.
Kaspersky reports the group is using Telegram & Discord as C2 servers to hide attacks on government networks in Russia & Central Asia.
Its new malware — written in Python, Rust, Go, PowerShell & C#.
GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools.
University of Pennsylvania joins list of victims from Clop's Oracle EBS raid.
Malicious Rust Crate Delivers OS-Specific Malware to Web3 Developer Systems.
GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections.
Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts.
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution.
Sanctioned but Still Spying: Intellexa’s Prolific Zero-Day Exploits Continue.